<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.ubuntu-nl.org/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Ubuntu security notices</title>
    <link>http://www.ubuntu.com/usn/</link>
    <language>en</language>
    <managingEditor>Dennis Kaarsemaker dennis@kaarsemaker.net</managingEditor>
    <webMaster>Dennis Kaarsemaker dennis@kaarsemaker.net</webMaster>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.ubuntu-nl.org/UbuntuSecurityNotices" type="application/rss+xml" /><item>
      <title>[USN-547-1] PCRE vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-547-1</guid>
      <link>http://www.ubuntu.com/usn/usn-547-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-547-1          November 27, 2007
pcre3 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1659"&gt;CVE-2007-1659&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1660"&gt;CVE-2007-1660&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1661"&gt;CVE-2007-1661&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1662"&gt;CVE-2007-1662&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4766"&gt;CVE-2007-4766&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4767"&gt;CVE-2007-4767&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4768"&gt;CVE-2007-4768&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpcre3 &lt;a href="http://launchpad.net/ubuntu/+source/libpcre3/7.4-0ubuntu0.6.06.1"&gt;7.4-0ubuntu0.6.06.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libpcrecpp0 &lt;a href="http://launchpad.net/ubuntu/+source/libpcrecpp0/7.4-0ubuntu0.6.06.1"&gt;7.4-0ubuntu0.6.06.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpcre3 &lt;a href="http://launchpad.net/ubuntu/+source/libpcre3/7.4-0ubuntu0.6.10.1"&gt;7.4-0ubuntu0.6.10.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libpcrecpp0 &lt;a href="http://launchpad.net/ubuntu/+source/libpcrecpp0/7.4-0ubuntu0.6.10.1"&gt;7.4-0ubuntu0.6.10.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpcre3 &lt;a href="http://launchpad.net/ubuntu/+source/libpcre3/7.4-0ubuntu0.7.04.1"&gt;7.4-0ubuntu0.7.04.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libpcrecpp0 &lt;a href="http://launchpad.net/ubuntu/+source/libpcrecpp0/7.4-0ubuntu0.7.04.1"&gt;7.4-0ubuntu0.7.04.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpcre3 &lt;a href="http://launchpad.net/ubuntu/+source/libpcre3/7.4-0ubuntu0.7.10.1"&gt;7.4-0ubuntu0.7.10.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libpcrecpp0 &lt;a href="http://launchpad.net/ubuntu/+source/libpcrecpp0/7.4-0ubuntu0.7.10.1"&gt;7.4-0ubuntu0.7.10.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.&lt;/p&gt;&lt;p&gt;Due to the large internal code changes needed to solve outstanding flaws,
it was not possible to backport all the upstream security fixes to the
earlier released versions.  To address this, the pcre3 library has been
updated to the latest stable release (7.4), which includes fixes for
all known security issues.  While the new version is ABI compatible,
efforts have been taken to maintain behavioral compatibility with the
earlier versions.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Tavis Ormandy and Will Drewry discovered multiple flaws in the regular
expression handling of PCRE.  By tricking a user or service into running
specially crafted expressions via applications linked against libpcre3,
a remote attacker could crash the application, monopolize CPU resources,
or possibly execute arbitrary code with the application's privileges.
&lt;/p&gt;

      </description>
      <pubDate>Tue, 27 Nov 2007 02:58:12 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-548-1] Pidgin vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-548-1</guid>
      <link>http://www.ubuntu.com/usn/usn-548-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-548-1          November 28, 2007
pidgin vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4999"&gt;CVE-2007-4999&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpurple0 &lt;a href="http://launchpad.net/ubuntu/+source/libpurple0/1:2.2.1-1ubuntu4.1"&gt;1:2.2.1-1ubuntu4.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart Pidgin to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that Pidgin did not correctly handle certain logging
events.  A remote attacker could send specially crafted messages and cause
the application to crash, leading to a denial of service.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 28 Nov 2007 23:29:45 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-549-1] PHP vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-549-1</guid>
      <link>http://www.ubuntu.com/usn/usn-549-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-549-1          November 29, 2007
php5 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1285"&gt;CVE-2007-1285&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-2872"&gt;CVE-2007-2872&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3799"&gt;CVE-2007-3799&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3998"&gt;CVE-2007-3998&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4657"&gt;CVE-2007-4657&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4658"&gt;CVE-2007-4658&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4660"&gt;CVE-2007-4660&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4661"&gt;CVE-2007-4661&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4662"&gt;CVE-2007-4662&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4670"&gt;CVE-2007-4670&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5898"&gt;CVE-2007-5898&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5899"&gt;CVE-2007-5899&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libapache2-mod-php5 &lt;a href="http://launchpad.net/ubuntu/+source/libapache2-mod-php5/5.1.2-1ubuntu3.10"&gt;5.1.2-1ubuntu3.10&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cgi &lt;a href="http://launchpad.net/ubuntu/+source/php5-cgi/5.1.2-1ubuntu3.10"&gt;5.1.2-1ubuntu3.10&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cli &lt;a href="http://launchpad.net/ubuntu/+source/php5-cli/5.1.2-1ubuntu3.10"&gt;5.1.2-1ubuntu3.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libapache2-mod-php5 &lt;a href="http://launchpad.net/ubuntu/+source/libapache2-mod-php5/5.1.6-1ubuntu2.7"&gt;5.1.6-1ubuntu2.7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cgi &lt;a href="http://launchpad.net/ubuntu/+source/php5-cgi/5.1.6-1ubuntu2.7"&gt;5.1.6-1ubuntu2.7&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cli &lt;a href="http://launchpad.net/ubuntu/+source/php5-cli/5.1.6-1ubuntu2.7"&gt;5.1.6-1ubuntu2.7&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libapache2-mod-php5 &lt;a href="http://launchpad.net/ubuntu/+source/libapache2-mod-php5/5.2.1-0ubuntu1.5"&gt;5.2.1-0ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cgi &lt;a href="http://launchpad.net/ubuntu/+source/php5-cgi/5.2.1-0ubuntu1.5"&gt;5.2.1-0ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cli &lt;a href="http://launchpad.net/ubuntu/+source/php5-cli/5.2.1-0ubuntu1.5"&gt;5.2.1-0ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libapache2-mod-php5 &lt;a href="http://launchpad.net/ubuntu/+source/libapache2-mod-php5/5.2.3-1ubuntu6.1"&gt;5.2.3-1ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cgi &lt;a href="http://launchpad.net/ubuntu/+source/php5-cgi/5.2.3-1ubuntu6.1"&gt;5.2.3-1ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cli &lt;a href="http://launchpad.net/ubuntu/+source/php5-cli/5.2.3-1ubuntu6.1"&gt;5.2.3-1ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that the wordwrap function did not correctly
check lengths.  Remote attackers could exploit this to cause
a crash or monopolize CPU resources, resulting in a denial of
service. (CVE-2007-3998)&lt;/p&gt;&lt;p&gt;Integer overflows were discovered in the strspn and strcspn functions.
Attackers could exploit this to read arbitrary areas of memory, possibly
gaining access to sensitive information. (CVE-2007-4657)&lt;/p&gt;&lt;p&gt;Stanislav Malyshev discovered that money_format function did not correctly
handle certain tokens.  If a PHP application were tricked into processing
a bad format string, a remote attacker could execute arbitrary code with
application privileges. (CVE-2007-4658)&lt;/p&gt;&lt;p&gt;It was discovered that the php_openssl_make_REQ function did not
correctly check buffer lengths.  A remote attacker could send a
specially crafted message and execute arbitrary code with application
privileges. (CVE-2007-4662)&lt;/p&gt;&lt;p&gt;It was discovered that certain characters in session cookies were not
handled correctly.  A remote attacker could injection values which could
lead to altered application behavior, potentially gaining additional
privileges. (CVE-2007-3799)&lt;/p&gt;&lt;p&gt;Gerhard Wagner discovered that the chunk_split function did not
correctly handle long strings.  A remote attacker could exploit this
to execute arbitrary code with application privileges.  (CVE-2007-2872,
CVE-2007-4660, CVE-2007-4661)&lt;/p&gt;&lt;p&gt;Stefan Esser discovered that deeply nested arrays could be made to
fill stack space.  A remote attacker could exploit this to cause a
crash or monopolize CPU resources, resulting in a denial of service.
(CVE-2007-1285, CVE-2007-4670)&lt;/p&gt;&lt;p&gt;Rasmus Lerdorf discovered that the htmlentities and htmlspecialchars
functions did not correctly stop when handling partial multibyte
sequences.  A remote attacker could exploit this to read certain areas of
memory, possibly gaining access to sensitive information. (CVE-2007-5898)&lt;/p&gt;&lt;p&gt;It was discovered that the output_add_rewrite_var fucntion would
sometimes leak session id information to forms targeting remote URLs.
Malicious remote sites could use this information to gain access to a
PHP application user's login credentials. (CVE-2007-5899)
&lt;/p&gt;

      </description>
      <pubDate>Thu, 29 Nov 2007 22:45:40 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-550-1] Cairo vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-550-1</guid>
      <link>http://www.ubuntu.com/usn/usn-550-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-550-1          December 03, 2007
libcairo vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5503"&gt;CVE-2007-5503&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.0.4-0ubuntu1.1"&gt;1.0.4-0ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.2.4-1ubuntu2.1"&gt;1.2.4-1ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.2-0ubuntu1.1"&gt;1.4.2-0ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.10-1ubuntu4.1"&gt;1.4.10-1ubuntu4.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Peter Valchev discovered that Cairo did not correctly decode PNG image data.
By tricking a user or automated system into processing a specially crafted
PNG with Cairo, a remote attacker could execute arbitrary code with user
privileges.
&lt;/p&gt;

      </description>
      <pubDate>Mon, 03 Dec 2007 21:42:42 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-551-1] OpenLDAP vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-551-1</guid>
      <link>http://www.ubuntu.com/usn/usn-551-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-551-1          December 04, 2007
openldap vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5707"&gt;CVE-2007-5707&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5708"&gt;CVE-2007-5708&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;slapd &lt;a href="http://launchpad.net/ubuntu/+source/slapd/2.2.26-5ubuntu2.4"&gt;2.2.26-5ubuntu2.4&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;slapd &lt;a href="http://launchpad.net/ubuntu/+source/slapd/2.2.26-5ubuntu3.2"&gt;2.2.26-5ubuntu3.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;slapd &lt;a href="http://launchpad.net/ubuntu/+source/slapd/2.3.30-2ubuntu0.1"&gt;2.3.30-2ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;slapd &lt;a href="http://launchpad.net/ubuntu/+source/slapd/2.3.35-1ubuntu0.1"&gt;2.3.35-1ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Thomas Sesselmann discovered that the OpenLDAP slapd server
did not properly handle certain modify requests. A remote
attacker could send malicious modify requests to the server
and cause a denial of service. (CVE-2007-5707)&lt;/p&gt;&lt;p&gt;Toby Blake discovered that slapd did not properly terminate
an array while running as a proxy-caching server. A remote
attacker may be able to send crafted search requests to the
server and cause a denial of service. This issue only affects
Ubuntu 7.04 and 7.10. (CVE-2007-5708)
&lt;/p&gt;

      </description>
      <pubDate>Tue, 04 Dec 2007 03:16:06 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-549-2] PHP regression</title>
      <guid>http://www.ubuntu.com/usn/usn-549-2</guid>
      <link>http://www.ubuntu.com/usn/usn-549-2</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-549-2          December 03, 2007
php5 regression
&lt;a href="https://launchpad.net/bugs/173043"&gt;Bug 173043&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libapache2-mod-php5 &lt;a href="http://launchpad.net/ubuntu/+source/libapache2-mod-php5/5.2.3-1ubuntu6.2"&gt;5.2.3-1ubuntu6.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cgi &lt;a href="http://launchpad.net/ubuntu/+source/php5-cgi/5.2.3-1ubuntu6.2"&gt;5.2.3-1ubuntu6.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;php5-cli &lt;a href="http://launchpad.net/ubuntu/+source/php5-cli/5.2.3-1ubuntu6.2"&gt;5.2.3-1ubuntu6.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
USN-549-1 fixed vulnerabilities in PHP.  However, some upstream changes
were incomplete, which caused crashes in certain situations with Ubuntu
7.10.  This update fixes the problem.&lt;/p&gt;&lt;p&gt;We apologize for the inconvenience.&lt;/p&gt;&lt;p&gt;Original advisory details:&lt;/p&gt;&lt;p&gt; It was discovered that the wordwrap function did not correctly
 check lengths.  Remote attackers could exploit this to cause
 a crash or monopolize CPU resources, resulting in a denial of
 service. (CVE-2007-3998)&lt;/p&gt;&lt;p&gt; Integer overflows were discovered in the strspn and strcspn functions.
 Attackers could exploit this to read arbitrary areas of memory, possibly
 gaining access to sensitive information. (CVE-2007-4657)&lt;/p&gt;&lt;p&gt; Stanislav Malyshev discovered that money_format function did not correctly
 handle certain tokens.  If a PHP application were tricked into processing
 a bad format string, a remote attacker could execute arbitrary code with
 application privileges. (CVE-2007-4658)&lt;/p&gt;&lt;p&gt; It was discovered that the php_openssl_make_REQ function did not
 correctly check buffer lengths.  A remote attacker could send a
 specially crafted message and execute arbitrary code with application
 privileges. (CVE-2007-4662)&lt;/p&gt;&lt;p&gt; It was discovered that certain characters in session cookies were not
 handled correctly.  A remote attacker could injection values which could
 lead to altered application behavior, potentially gaining additional
 privileges. (CVE-2007-3799)&lt;/p&gt;&lt;p&gt; Gerhard Wagner discovered that the chunk_split function did not
 correctly handle long strings.  A remote attacker could exploit this
 to execute arbitrary code with application privileges.  (CVE-2007-2872,
 CVE-2007-4660, CVE-2007-4661)&lt;/p&gt;&lt;p&gt; Stefan Esser discovered that deeply nested arrays could be made to
 fill stack space.  A remote attacker could exploit this to cause a
 crash or monopolize CPU resources, resulting in a denial of service.
 (CVE-2007-1285, CVE-2007-4670)&lt;/p&gt;&lt;p&gt; Rasmus Lerdorf discovered that the htmlentities and htmlspecialchars
 functions did not correctly stop when handling partial multibyte
 sequences.  A remote attacker could exploit this to read certain areas of
 memory, possibly gaining access to sensitive information. (CVE-2007-5898)&lt;/p&gt;&lt;p&gt; It was discovered that the output_add_rewrite_var fucntion would
 sometimes leak session id information to forms targeting remote URLs.
 Malicious remote sites could use this information to gain access to a
 PHP application user's login credentials. (CVE-2007-5899)
&lt;/p&gt;

      </description>
      <pubDate>Tue, 04 Dec 2007 03:45:53 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-546-2] Firefox regression</title>
      <guid>http://www.ubuntu.com/usn/usn-546-2</guid>
      <link>http://www.ubuntu.com/usn/usn-546-2</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-546-2          December 04, 2007
firefox regression
&lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id"&gt;https://bugzilla.mozilla.org/show_bug.cgi?id&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.11+0nobinonly-0ubuntu0.6.10"&gt;2.0.0.11+0nobinonly-0ubuntu0.6.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.11+1nobinonly-0ubuntu0.7.4"&gt;2.0.0.11+1nobinonly-0ubuntu0.7.4&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.11+2nobinonly-0ubuntu0.7.10"&gt;2.0.0.11+2nobinonly-0ubuntu0.7.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart Firefox to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
USN-546-1 fixed vulnerabilities in Firefox. The upstream update included
a faulty patch which caused the drawImage method of the canvas element to
fail.  This update fixes the problem.&lt;/p&gt;&lt;p&gt;We apologize for the inconvenience.&lt;/p&gt;&lt;p&gt;Original advisory details:&lt;/p&gt;&lt;p&gt; It was discovered that Firefox incorrectly associated redirected sites
 as the origin of "jar:" contents. A malicious web site could exploit this
 to modify or steal confidential data (such as passwords) from other web
 sites. (CVE-2007-5947)
 
 Various flaws were discovered in the layout and JavaScript engines. By
 tricking a user into opening a malicious web page, an attacker could
 execute arbitrary code with the user's privileges. (CVE-2007-5959)
 
 Gregory Fleischer discovered that it was possible to use JavaScript to
 manipulate Firefox's Referer header.  A malicious web site could exploit
 this to conduct cross-site request forgeries against sites that relied
 only on Referer headers for protection from such attacks. (CVE-2007-5960)
&lt;/p&gt;

      </description>
      <pubDate>Tue, 04 Dec 2007 20:56:11 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-552-1] Perl vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-552-1</guid>
      <link>http://www.ubuntu.com/usn/usn-552-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-552-1          December 04, 2007
perl vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5116"&gt;CVE-2007-5116&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libperl5.8 &lt;a href="http://launchpad.net/ubuntu/+source/libperl5.8/5.8.7-10ubuntu1.1"&gt;5.8.7-10ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libperl5.8 &lt;a href="http://launchpad.net/ubuntu/+source/libperl5.8/5.8.8-6ubuntu0.1"&gt;5.8.8-6ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libperl5.8 &lt;a href="http://launchpad.net/ubuntu/+source/libperl5.8/5.8.8-7ubuntu0.1"&gt;5.8.8-7ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libperl5.8 &lt;a href="http://launchpad.net/ubuntu/+source/libperl5.8/5.8.8-7ubuntu3.1"&gt;5.8.8-7ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that Perl's regular expression library did not correctly
handle certain UTF sequences.  If a user or automated system were tricked
into running a specially crafted regular expression, a remote attacker
could crash the application or possibly execute arbitrary code with
user privileges.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 05 Dec 2007 00:07:16 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-553-1] Mono vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-553-1</guid>
      <link>http://www.ubuntu.com/usn/usn-553-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-553-1          December 04, 2007
mono vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5197"&gt;CVE-2007-5197&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;mono-classlib-1.0 &lt;a href="http://launchpad.net/ubuntu/+source/mono-classlib-1.0/1.1.13.6-0ubuntu3.3"&gt;1.1.13.6-0ubuntu3.3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;mono-classlib-2.0 &lt;a href="http://launchpad.net/ubuntu/+source/mono-classlib-2.0/1.1.13.6-0ubuntu3.3"&gt;1.1.13.6-0ubuntu3.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libmono-corlib1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib1.0-cil/1.1.17.1-1ubuntu7.2"&gt;1.1.17.1-1ubuntu7.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-corlib2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib2.0-cil/1.1.17.1-1ubuntu7.2"&gt;1.1.17.1-1ubuntu7.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security1.0-cil/1.1.17.1-1ubuntu7.2"&gt;1.1.17.1-1ubuntu7.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security2.0-cil/1.1.17.1-1ubuntu7.2"&gt;1.1.17.1-1ubuntu7.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libmono-corlib1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib1.0-cil/1.2.3.1-1ubuntu1.1"&gt;1.2.3.1-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-corlib2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib2.0-cil/1.2.3.1-1ubuntu1.1"&gt;1.2.3.1-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security1.0-cil/1.2.3.1-1ubuntu1.1"&gt;1.2.3.1-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security2.0-cil/1.2.3.1-1ubuntu1.1"&gt;1.2.3.1-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libmono-corlib1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib1.0-cil/1.2.4-6ubuntu6.1"&gt;1.2.4-6ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-corlib2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-corlib2.0-cil/1.2.4-6ubuntu6.1"&gt;1.2.4-6ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security1.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security1.0-cil/1.2.4-6ubuntu6.1"&gt;1.2.4-6ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libmono-security2.0-cil &lt;a href="http://launchpad.net/ubuntu/+source/libmono-security2.0-cil/1.2.4-6ubuntu6.1"&gt;1.2.4-6ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that Mono did not correctly bounds check certain BigInteger
actions.  Remote attackers could exploit this to crash a Mono application or
possibly execute arbitrary code with user privileges.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 05 Dec 2007 00:08:19 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-554-1] teTeX and TeX Live vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-554-1</guid>
      <link>http://www.ubuntu.com/usn/usn-554-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-554-1          December 06, 2007
tetex-bin, texlive-bin vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5935"&gt;CVE-2007-5935&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5936"&gt;CVE-2007-5936&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5937"&gt;CVE-2007-5937&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tetex-bin &lt;a href="http://launchpad.net/ubuntu/+source/tetex-bin/3.0-13ubuntu6.1"&gt;3.0-13ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tetex-bin &lt;a href="http://launchpad.net/ubuntu/+source/tetex-bin/3.0-17ubuntu2.1"&gt;3.0-17ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tetex-bin &lt;a href="http://launchpad.net/ubuntu/+source/tetex-bin/3.0-27ubuntu1.2"&gt;3.0-27ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;texlive-extra-utils &lt;a href="http://launchpad.net/ubuntu/+source/texlive-extra-utils/2007-12ubuntu3.1"&gt;2007-12ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Bastien Roucaries discovered that dvips as included in tetex-bin
and texlive-bin did not properly perform bounds checking. If a
user or automated system were tricked into processing a specially
crafted dvi file, dvips could be made to crash and execute code as
the user invoking the program. (CVE-2007-5935)&lt;/p&gt;&lt;p&gt;Joachim Schrod discovered that the dviljk utilities created
temporary files in an insecure way. Local users could exploit a
race condition to create or overwrite files with the privileges of
the user invoking the program. (CVE-2007-5936)&lt;/p&gt;&lt;p&gt;Joachim Schrod discovered that the dviljk utilities did not
perform bounds checking in many instances. If a user or automated
system were tricked into processing a specially crafted dvi file,
the dviljk utilities could be made to crash and execute code as
the user invoking the program. (CVE-2007-5937)
&lt;/p&gt;

      </description>
      <pubDate>Thu, 06 Dec 2007 21:04:59 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-555-1] e2fsprogs vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-555-1</guid>
      <link>http://www.ubuntu.com/usn/usn-555-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-555-1          December 08, 2007
e2fsprogs vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5497"&gt;CVE-2007-5497&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;e2fslibs &lt;a href="http://launchpad.net/ubuntu/+source/e2fslibs/1.38-2ubuntu2.1"&gt;1.38-2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;e2fslibs &lt;a href="http://launchpad.net/ubuntu/+source/e2fslibs/1.39-1ubuntu0.1"&gt;1.39-1ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;e2fslibs &lt;a href="http://launchpad.net/ubuntu/+source/e2fslibs/1.39+1.40-WIP-2006.11.14+dfsg-2ubuntu1.1"&gt;1.39+1.40-WIP-2006.11.14+dfsg-2ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;e2fslibs &lt;a href="http://launchpad.net/ubuntu/+source/e2fslibs/1.40.2-1ubuntu1.1"&gt;1.40.2-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Rafal Wojtczuk discovered multiple integer overflows in e2fsprogs.  If a
user or automated system were tricked into fscking a malicious ext2/ext3
filesystem, a remote attacker could execute arbitrary code with the user's
privileges.
&lt;/p&gt;

      </description>
      <pubDate>Sat, 08 Dec 2007 04:56:09 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-550-2] Cairo regression</title>
      <guid>http://www.ubuntu.com/usn/usn-550-2</guid>
      <link>http://www.ubuntu.com/usn/usn-550-2</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-550-2          December 10, 2007
libcairo regression
&lt;a href="https://launchpad.net/bugs/NNNNNN"&gt;https://launchpad.net/bugs/NNNNNN&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.2-0ubuntu1.2"&gt;1.4.2-0ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.10-1ubuntu4.2"&gt;1.4.10-1ubuntu4.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
USN-550-1 fixed vulnerabilities in Cairo.  The upstream fixes were incomplete,
and under certain situations, applications using Cairo would crash with a
floating point error.  This update fixes the problem.&lt;/p&gt;&lt;p&gt;We apologize for the inconvenience.&lt;/p&gt;&lt;p&gt;Original advisory details:&lt;/p&gt;&lt;p&gt; Peter Valchev discovered that Cairo did not correctly decode PNG image data.
 By tricking a user or automated system into processing a specially crafted
 PNG with Cairo, a remote attacker could execute arbitrary code with user
 privileges.
&lt;/p&gt;

      </description>
      <pubDate>Mon, 10 Dec 2007 20:36:29 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-550-3] Cairo regression</title>
      <guid>http://www.ubuntu.com/usn/usn-550-3</guid>
      <link>http://www.ubuntu.com/usn/usn-550-3</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-550-3          December 13, 2007
libcairo regression
&lt;a href="https://launchpad.net/bugs/175573"&gt;Bug 175573&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.0.4-0ubuntu1.2"&gt;1.0.4-0ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.2.4-1ubuntu2.2"&gt;1.2.4-1ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.2-0ubuntu1.3"&gt;1.4.2-0ubuntu1.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libcairo2 &lt;a href="http://launchpad.net/ubuntu/+source/libcairo2/1.4.10-1ubuntu4.4"&gt;1.4.10-1ubuntu4.4&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
USN-550-1 fixed vulnerabilities in Cairo.  A bug in font glyph rendering
was uncovered as a result of the new memory allocation routines.  In
certain situations, fonts containing characters with no width or height
would not render any more.  This update fixes the problem.&lt;/p&gt;&lt;p&gt;We apologize for the inconvenience.&lt;/p&gt;&lt;p&gt;Original advisory details:&lt;/p&gt;&lt;p&gt; Peter Valchev discovered that Cairo did not correctly decode PNG image data.
 By tricking a user or automated system into processing a specially crafted
 PNG with Cairo, a remote attacker could execute arbitrary code with user
 privileges.
&lt;/p&gt;

      </description>
      <pubDate>Thu, 13 Dec 2007 04:18:42 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-556-1] Samba vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-556-1</guid>
      <link>http://www.ubuntu.com/usn/usn-556-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-556-1          December 18, 2007
samba vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6015"&gt;CVE-2007-6015&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libsmbclient &lt;a href="http://launchpad.net/ubuntu/+source/libsmbclient/3.0.22-1ubuntu3.6"&gt;3.0.22-1ubuntu3.6&lt;/a&gt;&lt;/li&gt;&lt;li&gt;samba &lt;a href="http://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.6"&gt;3.0.22-1ubuntu3.6&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libsmbclient &lt;a href="http://launchpad.net/ubuntu/+source/libsmbclient/3.0.22-1ubuntu4.5"&gt;3.0.22-1ubuntu4.5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;samba &lt;a href="http://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu4.5"&gt;3.0.22-1ubuntu4.5&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libsmbclient &lt;a href="http://launchpad.net/ubuntu/+source/libsmbclient/3.0.24-2ubuntu1.5"&gt;3.0.24-2ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;li&gt;samba &lt;a href="http://launchpad.net/ubuntu/+source/samba/3.0.24-2ubuntu1.5"&gt;3.0.24-2ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libsmbclient &lt;a href="http://launchpad.net/ubuntu/+source/libsmbclient/3.0.26a-1ubuntu2.3"&gt;3.0.26a-1ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;samba &lt;a href="http://launchpad.net/ubuntu/+source/samba/3.0.26a-1ubuntu2.3"&gt;3.0.26a-1ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Alin Rad Pop discovered that Samba did not correctly check the size
of reply packets to mailslot requests.  If a server was configured
with domain logon enabled, an unauthenticated remote attacker could send
a specially crafted domain logon packet and execute arbitrary code or
crash the Samba service.  By default, domain logon is disabled in Ubuntu.
&lt;/p&gt;

      </description>
      <pubDate>Tue, 18 Dec 2007 19:27:46 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-557-1] GD library vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-557-1</guid>
      <link>http://www.ubuntu.com/usn/usn-557-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-557-1          December 18, 2007
libgd2 vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3996"&gt;CVE-2007-3996&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libgd2-noxpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-noxpm/2.0.33-2ubuntu5.3"&gt;2.0.33-2ubuntu5.3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libgd2-xpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-xpm/2.0.33-2ubuntu5.3"&gt;2.0.33-2ubuntu5.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libgd2-noxpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-noxpm/2.0.33-4ubuntu2.2"&gt;2.0.33-4ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libgd2-xpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-xpm/2.0.33-4ubuntu2.2"&gt;2.0.33-4ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libgd2-noxpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-noxpm/2.0.34~rc1-2ubuntu1.2"&gt;2.0.34~rc1-2ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libgd2-xpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-xpm/2.0.34~rc1-2ubuntu1.2"&gt;2.0.34~rc1-2ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libgd2-noxpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-noxpm/2.0.34-1ubuntu1.1"&gt;2.0.34-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;libgd2-xpm &lt;a href="http://launchpad.net/ubuntu/+source/libgd2-xpm/2.0.34-1ubuntu1.1"&gt;2.0.34-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Mattias Bengtsson and Philip Olausson discovered that the GD
library did not properly perform bounds checking when creating
images. An attacker could send specially crafted input to
applications linked against libgd2 and cause a denial of service
or possibly execute arbitrary code.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 19 Dec 2007 01:34:03 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-558-1] Linux kernel vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-558-1</guid>
      <link>http://www.ubuntu.com/usn/usn-558-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-558-1          December 19, 2007
linux-source-2.6.17/20/22 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-6058"&gt;CVE-2006-6058&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4133"&gt;CVE-2007-4133&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4567"&gt;CVE-2007-4567&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4849"&gt;CVE-2007-4849&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4997"&gt;CVE-2007-4997&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5093"&gt;CVE-2007-5093&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5500"&gt;CVE-2007-5500&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5501"&gt;CVE-2007-5501&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.17-12-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-386/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-generic/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-hppa32/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-hppa64/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-itanium/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-mckinley/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc-smp/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc64-smp/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-server/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-server-bigiron &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-server-bigiron/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-sparc64/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-sparc64-smp/2.6.17.1-12.42"&gt;2.6.17.1-12.42&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.20-16-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-386/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-generic/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-hppa32/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-hppa64/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-itanium/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-lowlatency &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-lowlatency/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-mckinley/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc-smp/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc64-smp/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-server/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-server-bigiron &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-server-bigiron/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-sparc64/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-sparc64-smp/2.6.20-16.33"&gt;2.6.20-16.33&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.22-14-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-386/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-cell &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-cell/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-generic/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-hppa32/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-hppa64/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-itanium/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-lpia &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-lpia/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-lpiacompat &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-lpiacompat/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-mckinley/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc-smp/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc64-smp/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-rt &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-rt/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-server/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-sparc64/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-sparc64-smp/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-ume &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-ume/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-virtual &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-virtual/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-xen &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-xen/2.6.22-14.47"&gt;2.6.22-14.47&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
The minix filesystem did not properly validate certain filesystem values.
If a local attacker could trick the system into attempting to mount a
corrupted minix filesystem, the kernel could be made to hang for long
periods of time, resulting in a denial of service. (CVE-2006-6058)&lt;/p&gt;&lt;p&gt;Certain calculations in the hugetlb code were not correct.  A local
attacker could exploit this to cause a kernel panic, leading to a denial
of service. (CVE-2007-4133)&lt;/p&gt;&lt;p&gt;Eric Sesterhenn and Victor Julien discovered that the hop-by-hop IPv6
extended header was not correctly validated.  If a system was configured
for IPv6, a remote attacker could send a specially crafted IPv6 packet
and cause the kernel to panic, leading to a denial of service.  This
was only vulnerable in Ubuntu 7.04. (CVE-2007-4567)&lt;/p&gt;&lt;p&gt;Permissions were not correctly stored on JFFS2 ACLs.  For systems using
ACLs on JFFS2, a local attacker may gain access to private files.
(CVE-2007-4849)&lt;/p&gt;&lt;p&gt;Chris Evans discovered that the 802.11 network stack did not correctly
handle certain QOS frames.  A remote attacker on the local wireless network
could send specially crafted packets that would panic the kernel, resulting
in a denial of service. (CVE-2007-4997)&lt;/p&gt;&lt;p&gt;The Philips USB Webcam driver did not correctly handle disconnects.
If a local attacker tricked another user into disconnecting a webcam
unsafely, the kernel could hang or consume CPU resources, leading to
a denial of service. (CVE-2007-5093)&lt;/p&gt;&lt;p&gt;Scott James Remnant discovered that the waitid function could be made
to hang the system.  A local attacker could execute a specially crafted
program which would leave the system unresponsive, resulting in a denial
of service. (CVE-2007-5500)&lt;/p&gt;&lt;p&gt;Ilpo Järvinen discovered that it might be possible for the TCP stack
to panic the kernel when receiving a crafted ACK response.  Only Ubuntu
7.10 contained the vulnerable code, and it is believed not to have
been exploitable. (CVE-2007-5501)&lt;/p&gt;&lt;p&gt;When mounting the same remote NFS share to separate local locations, the
first location's mount options would apply to all subsequent mounts of the
same NFS share.  In some configurations, this could lead to incorrectly
configured permissions, allowing local users to gain additional access
to the mounted share. (https://launchpad.net/bugs/164231)
&lt;/p&gt;

      </description>
      <pubDate>Wed, 19 Dec 2007 03:38:34 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-559-1] MySQL vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-559-1</guid>
      <link>http://www.ubuntu.com/usn/usn-559-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-559-1          December 21, 2007
mysql-dfsg-5.0 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3781"&gt;CVE-2007-3781&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5925"&gt;CVE-2007-5925&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5969"&gt;CVE-2007-5969&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6304"&gt;CVE-2007-6304&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;mysql-server-5.0 &lt;a href="http://launchpad.net/ubuntu/+source/mysql-server-5.0/5.0.22-0ubuntu6.06.6"&gt;5.0.22-0ubuntu6.06.6&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;mysql-server-5.0 &lt;a href="http://launchpad.net/ubuntu/+source/mysql-server-5.0/5.0.24a-9ubuntu2.2"&gt;5.0.24a-9ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;mysql-server-5.0 &lt;a href="http://launchpad.net/ubuntu/+source/mysql-server-5.0/5.0.38-0ubuntu1.2"&gt;5.0.38-0ubuntu1.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;mysql-server-5.0 &lt;a href="http://launchpad.net/ubuntu/+source/mysql-server-5.0/5.0.45-1ubuntu3.1"&gt;5.0.45-1ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Joe Gallo and Artem Russakovskii discovered that the InnoDB
engine in MySQL did not properly perform input validation. An
authenticated user could use a crafted CONTAINS statement to
cause a denial of service. (CVE-2007-5925)&lt;/p&gt;&lt;p&gt;It was discovered that under certain conditions MySQL could be
made to overwrite system table information. An authenticated
user could use a crafted RENAME statement to escalate privileges.
(CVE-2007-5969)&lt;/p&gt;&lt;p&gt;Philip Stoev discovered that the the federated engine of MySQL
did not properly handle responses with a small number of columns.
An authenticated user could use a crafted response to a SHOW
TABLE STATUS query and cause a denial of service. (CVE-2007-6304)&lt;/p&gt;&lt;p&gt;It was discovered that MySQL did not properly enforce access
controls. An authenticated user could use a crafted CREATE TABLE
LIKE statement to escalate privileges. (CVE-2007-3781)
&lt;/p&gt;

      </description>
      <pubDate>Fri, 21 Dec 2007 07:25:53 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-560-1] Tomboy vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-560-1</guid>
      <link>http://www.ubuntu.com/usn/usn-560-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-560-1           January 07, 2008
tomboy vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-4790"&gt;CVE-2005-4790&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tomboy &lt;a href="http://launchpad.net/ubuntu/+source/tomboy/0.3.5-1ubuntu3.1"&gt;0.3.5-1ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tomboy &lt;a href="http://launchpad.net/ubuntu/+source/tomboy/0.4.1-0ubuntu3.1"&gt;0.4.1-0ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tomboy &lt;a href="http://launchpad.net/ubuntu/+source/tomboy/0.6.3-0ubuntu1.1"&gt;0.6.3-0ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;tomboy &lt;a href="http://launchpad.net/ubuntu/+source/tomboy/0.8.0-1ubuntu0.1"&gt;0.8.0-1ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart Tomboy to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Jan Oravec discovered that Tomboy did not properly setup the
LD_LIBRARY_PATH environment variable. A local attacker could
exploit this to execute arbitrary code as the user invoking
the program.
&lt;/p&gt;

      </description>
      <pubDate>Tue, 08 Jan 2008 02:04:32 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-561-1] pwlib vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-561-1</guid>
      <link>http://www.ubuntu.com/usn/usn-561-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-561-1           January 08, 2008
pwlib vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4897"&gt;CVE-2007-4897&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpt-1.10.0 &lt;a href="http://launchpad.net/ubuntu/+source/libpt-1.10.0/1.10.0-1ubuntu1.1"&gt;1.10.0-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpt-1.10.0 &lt;a href="http://launchpad.net/ubuntu/+source/libpt-1.10.0/1.10.2.dfsg-0ubuntu3.1"&gt;1.10.2.dfsg-0ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpt-1.10.0 &lt;a href="http://launchpad.net/ubuntu/+source/libpt-1.10.0/1.10.3-0ubuntu1.1"&gt;1.10.3-0ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libpt-1.10.0 &lt;a href="http://launchpad.net/ubuntu/+source/libpt-1.10.0/1.10.10-0ubuntu2.1"&gt;1.10.10-0ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Jose Miguel Esparza discovered that pwlib did not correctly handle large
string lengths.  A remote attacker could send specially crafted packets to
applications linked against pwlib (e.g. Ekiga) causing them to crash, leading
to a denial of service.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 09 Jan 2008 05:37:45 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-562-1] opal vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-562-1</guid>
      <link>http://www.ubuntu.com/usn/usn-562-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-562-1           January 08, 2008
opal vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4924"&gt;CVE-2007-4924&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libopal-2.2.0 &lt;a href="http://launchpad.net/ubuntu/+source/libopal-2.2.0/2.2.1-1ubuntu1.1"&gt;2.2.1-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libopal-2.2.0 &lt;a href="http://launchpad.net/ubuntu/+source/libopal-2.2.0/2.2.3.dfsg-0ubuntu2.1"&gt;2.2.3.dfsg-0ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libopal-2.2.0 &lt;a href="http://launchpad.net/ubuntu/+source/libopal-2.2.0/2.2.3.dfsg-2ubuntu2.1"&gt;2.2.3.dfsg-2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Jose Miguel Esparza discovered that certain SIP headers were not correctly
validated.  A remote attacker could send a specially crafted packet to
an application linked against opal (e.g. Ekiga) causing it to crash, leading
to a denial of service.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 09 Jan 2008 05:38:38 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-563-1] CUPS vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-563-1</guid>
      <link>http://www.ubuntu.com/usn/usn-563-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-563-1           January 09, 2008
cupsys vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5849"&gt;CVE-2007-5849&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6358"&gt;CVE-2007-6358&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;cupsys &lt;a href="http://launchpad.net/ubuntu/+source/cupsys/1.2.2-0ubuntu0.6.06.6"&gt;1.2.2-0ubuntu0.6.06.6&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;cupsys &lt;a href="http://launchpad.net/ubuntu/+source/cupsys/1.2.4-2ubuntu3.2"&gt;1.2.4-2ubuntu3.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;cupsys &lt;a href="http://launchpad.net/ubuntu/+source/cupsys/1.2.8-0ubuntu8.2"&gt;1.2.8-0ubuntu8.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;cupsys &lt;a href="http://launchpad.net/ubuntu/+source/cupsys/1.3.2-1ubuntu7.3"&gt;1.3.2-1ubuntu7.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Wei Wang discovered that the SNMP discovery backend did not correctly
calculate the length of strings.  If a user were tricked into scanning
for printers, a remote attacker could send a specially crafted packet
and possibly execute arbitrary code.&lt;/p&gt;&lt;p&gt;Elias Pipping discovered that temporary files were not handled safely
in certain situations when converting PDF to PS.  A local attacker could
cause a denial of service.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 09 Jan 2008 05:40:10 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-564-1] Net-SNMP vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-564-1</guid>
      <link>http://www.ubuntu.com/usn/usn-564-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-564-1           January 09, 2008
net-snmp vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5846"&gt;CVE-2007-5846&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;snmpd &lt;a href="http://launchpad.net/ubuntu/+source/snmpd/5.2.1.2-4ubuntu2.2"&gt;5.2.1.2-4ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;snmpd &lt;a href="http://launchpad.net/ubuntu/+source/snmpd/5.2.2-5ubuntu1.1"&gt;5.2.2-5ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;snmpd &lt;a href="http://launchpad.net/ubuntu/+source/snmpd/5.2.3-4ubuntu1.1"&gt;5.2.3-4ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;snmpd &lt;a href="http://launchpad.net/ubuntu/+source/snmpd/5.3.1-6ubuntu2.1"&gt;5.3.1-6ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Bill Trost discovered that snmpd did not properly limit GETBULK
requests. A remote attacker could specify a large number of
max-repetitions and cause a denial of service via resource
exhaustion.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 09 Jan 2008 14:53:30 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-565-1] Squid vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-565-1</guid>
      <link>http://www.ubuntu.com/usn/usn-565-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-565-1           January 09, 2008
squid vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6239"&gt;CVE-2007-6239&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;squid &lt;a href="http://launchpad.net/ubuntu/+source/squid/2.5.12-4ubuntu2.3"&gt;2.5.12-4ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;squid &lt;a href="http://launchpad.net/ubuntu/+source/squid/2.6.1-3ubuntu1.5"&gt;2.6.1-3ubuntu1.5&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;squid &lt;a href="http://launchpad.net/ubuntu/+source/squid/2.6.5-4ubuntu2.1"&gt;2.6.5-4ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;squid &lt;a href="http://launchpad.net/ubuntu/+source/squid/2.6.14-1ubuntu2.1"&gt;2.6.14-1ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that Squid did not always clean up cache memory
correctly.  A remote attacker could manipulate cache update replies and
cause Squid to use all available memory, leading to a denial of service.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 09 Jan 2008 22:22:24 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-566-1] OpenSSH vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-566-1</guid>
      <link>http://www.ubuntu.com/usn/usn-566-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-566-1           January 09, 2008
openssh vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4752"&gt;CVE-2007-4752&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;openssh-client &lt;a href="http://launchpad.net/ubuntu/+source/openssh-client/1:4.2p1-7ubuntu3.2"&gt;1:4.2p1-7ubuntu3.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;openssh-client &lt;a href="http://launchpad.net/ubuntu/+source/openssh-client/1:4.3p2-5ubuntu1.1"&gt;1:4.3p2-5ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;openssh-client &lt;a href="http://launchpad.net/ubuntu/+source/openssh-client/1:4.3p2-8ubuntu1.1"&gt;1:4.3p2-8ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;openssh-client &lt;a href="http://launchpad.net/ubuntu/+source/openssh-client/1:4.6p1-5ubuntu0.1"&gt;1:4.6p1-5ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Jan Pechanec discovered that ssh would forward trusted X11 cookies when
untrusted cookie generation failed.  This could lead to unintended privileges
being forwarded to a remote host.
&lt;/p&gt;

      </description>
      <pubDate>Thu, 10 Jan 2008 02:00:28 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-567-1] Dovecot vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-567-1</guid>
      <link>http://www.ubuntu.com/usn/usn-567-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-567-1           January 10, 2008
dovecot vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6598"&gt;CVE-2007-6598&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;dovecot-imapd &lt;a href="http://launchpad.net/ubuntu/+source/dovecot-imapd/1.0.rc17-1ubuntu2.2"&gt;1.0.rc17-1ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;dovecot-pop3d &lt;a href="http://launchpad.net/ubuntu/+source/dovecot-pop3d/1.0.rc17-1ubuntu2.2"&gt;1.0.rc17-1ubuntu2.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;dovecot-imapd &lt;a href="http://launchpad.net/ubuntu/+source/dovecot-imapd/1:1.0.5-1ubuntu2.1"&gt;1:1.0.5-1ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;dovecot-pop3d &lt;a href="http://launchpad.net/ubuntu/+source/dovecot-pop3d/1:1.0.5-1ubuntu2.1"&gt;1:1.0.5-1ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that in very rare configurations using LDAP, Dovecot may
reuse cached connections for users with the same password.  As a result,
a user may be able to login as another if the connection is reused.
The default Ubuntu configuration of Dovecot was not vulnerable.
&lt;/p&gt;

      </description>
      <pubDate>Thu, 10 Jan 2008 22:01:59 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-568-1] PostgreSQL vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-568-1</guid>
      <link>http://www.ubuntu.com/usn/usn-568-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-568-1           January 14, 2008
postgresql vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3278"&gt;CVE-2007-3278&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4769"&gt;CVE-2007-4769&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4772"&gt;CVE-2007-4772&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6067"&gt;CVE-2007-6067&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6600"&gt;CVE-2007-6600&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6601"&gt;CVE-2007-6601&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;postgresql-8.1 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.11-0ubuntu0.6.06.1"&gt;8.1.11-0ubuntu0.6.06.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;postgresql-pltcl-8.1 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-pltcl-8.1/8.1.11-0ubuntu0.6.06.1"&gt;8.1.11-0ubuntu0.6.06.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;postgresql-8.1 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-8.1/8.1.11-0ubuntu0.6.10.1"&gt;8.1.11-0ubuntu0.6.10.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;postgresql-pltcl-8.1 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-pltcl-8.1/8.1.11-0ubuntu0.6.10.1"&gt;8.1.11-0ubuntu0.6.10.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;postgresql-8.2 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-8.2/8.2.6-0ubuntu0.7.04.1"&gt;8.2.6-0ubuntu0.7.04.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;postgresql-pltcl-8.2 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-pltcl-8.2/8.2.6-0ubuntu0.7.04.1"&gt;8.2.6-0ubuntu0.7.04.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;postgresql-8.2 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-8.2/8.2.6-0ubuntu0.7.10.1"&gt;8.2.6-0ubuntu0.7.10.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;postgresql-pltcl-8.2 &lt;a href="http://launchpad.net/ubuntu/+source/postgresql-pltcl-8.2/8.2.6-0ubuntu0.7.10.1"&gt;8.2.6-0ubuntu0.7.10.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Nico Leidecker discovered that PostgreSQL did not properly
restrict dblink functions. An authenticated user could exploit
this flaw to access arbitrary accounts and execute arbitrary
SQL queries. (CVE-2007-3278, CVE-2007-6601)&lt;/p&gt;&lt;p&gt;It was discovered that the TCL regular expression parser used
by PostgreSQL did not properly check its input. An attacker
could send crafted regular expressions to PostgreSQL and cause
a denial of service via resource exhaustion or database crash.
(CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)&lt;/p&gt;&lt;p&gt;It was discovered that PostgreSQL executed VACUUM and ANALYZE
operations within index functions with superuser privileges and
also allowed SET ROLE and SET SESSION AUTHORIZATION within index
functions. A remote authenticated user could exploit these flaws
to gain privileges. (CVE-2007-6600)
&lt;/p&gt;

      </description>
      <pubDate>Mon, 14 Jan 2008 21:31:06 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-569-1] libxml2 vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-569-1</guid>
      <link>http://www.ubuntu.com/usn/usn-569-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-569-1           January 14, 2008
libxml2 vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6284"&gt;CVE-2007-6284&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxml2 &lt;a href="http://launchpad.net/ubuntu/+source/libxml2/2.6.24.dfsg-1ubuntu1.1"&gt;2.6.24.dfsg-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxml2 &lt;a href="http://launchpad.net/ubuntu/+source/libxml2/2.6.26.dfsg-2ubuntu4.1"&gt;2.6.26.dfsg-2ubuntu4.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxml2 &lt;a href="http://launchpad.net/ubuntu/+source/libxml2/2.6.27.dfsg-1ubuntu3.1"&gt;2.6.27.dfsg-1ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxml2 &lt;a href="http://launchpad.net/ubuntu/+source/libxml2/2.6.30.dfsg-2ubuntu1.1"&gt;2.6.30.dfsg-2ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Brad Fitzpatrick discovered that libxml2 did not correctly handle certain
UTF-8 sequences.  If a remote attacker were able to trick a user or
automated system into processing a specially crafted XML document, the
application linked against libxml2 could enter an infinite loop, leading
to a denial of service via CPU resource consumption.
&lt;/p&gt;

      </description>
      <pubDate>Tue, 15 Jan 2008 00:13:03 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-570-1] boost vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-570-1</guid>
      <link>http://www.ubuntu.com/usn/usn-570-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-570-1           January 16, 2008
boost vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0171"&gt;CVE-2008-0171&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0172"&gt;CVE-2008-0172&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libboost-regex1.33.1 &lt;a href="http://launchpad.net/ubuntu/+source/libboost-regex1.33.1/1.33.1-2ubuntu0.1"&gt;1.33.1-2ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libboost-regex1.33.1 &lt;a href="http://launchpad.net/ubuntu/+source/libboost-regex1.33.1/1.33.1-7ubuntu1.1"&gt;1.33.1-7ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libboost-regex1.33.1 &lt;a href="http://launchpad.net/ubuntu/+source/libboost-regex1.33.1/1.33.1-9ubuntu3.1"&gt;1.33.1-9ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libboost-regex1.34.1 &lt;a href="http://launchpad.net/ubuntu/+source/libboost-regex1.34.1/1.34.1-2ubuntu1.1"&gt;1.34.1-2ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Will Drewry and Tavis Ormandy discovered that the boost library 
did not properly perform input validation on regular expressions.
An attacker could send a specially crafted regular expression to
an application linked against boost and cause a denial of service
via application crash.
&lt;/p&gt;

      </description>
      <pubDate>Wed, 16 Jan 2008 22:45:38 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-571-1] X.org vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-571-1</guid>
      <link>http://www.ubuntu.com/usn/usn-571-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-571-1           January 18, 2008
libxfont, xorg-server vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5760"&gt;CVE-2007-5760&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5958"&gt;CVE-2007-5958&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6427"&gt;CVE-2007-6427&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6428"&gt;CVE-2007-6428&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6429"&gt;CVE-2007-6429&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0006"&gt;CVE-2008-0006&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxfont1 &lt;a href="http://launchpad.net/ubuntu/+source/libxfont1/1:1.0.0-0ubuntu3.4"&gt;1:1.0.0-0ubuntu3.4&lt;/a&gt;&lt;/li&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/1:1.0.2-0ubuntu10.8"&gt;1:1.0.2-0ubuntu10.8&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxfont1 &lt;a href="http://launchpad.net/ubuntu/+source/libxfont1/1:1.2.0-0ubuntu3.2"&gt;1:1.2.0-0ubuntu3.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/1:1.1.1-0ubuntu12.3"&gt;1:1.1.1-0ubuntu12.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxfont1 &lt;a href="http://launchpad.net/ubuntu/+source/libxfont1/1:1.2.7-1ubuntu1.1"&gt;1:1.2.7-1ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/2:1.2.0-3ubuntu8.1"&gt;2:1.2.0-3ubuntu8.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;libxfont1 &lt;a href="http://launchpad.net/ubuntu/+source/libxfont1/1:1.3.0-0ubuntu1.1"&gt;1:1.3.0-0ubuntu1.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/2:1.3.0.0.dfsg-12ubuntu8.1"&gt;2:1.3.0.0.dfsg-12ubuntu8.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
function arguments.  An authenticated attacker could send specially
crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
CVE-2007-6428, CVE-2007-6429)&lt;/p&gt;&lt;p&gt;It was discovered that the X.org server did not use user privileges when
attempting to open security policy files.  Local attackers could exploit
this to probe for files in directories they would not normally be able
to access.  (CVE-2007-5958)&lt;/p&gt;&lt;p&gt;It was discovered that the PCF font handling code did not correctly
validate the size of fonts.  An authenticated attacker could load a
specially crafted font and gain additional privileges.  (CVE-2008-0006)
&lt;/p&gt;

      </description>
      <pubDate>Fri, 18 Jan 2008 06:24:41 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-572-1] apt-listchanges vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-572-1</guid>
      <link>http://www.ubuntu.com/usn/usn-572-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-572-1           January 18, 2008
apt-listchanges vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0302"&gt;CVE-2008-0302&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apt-listchanges &lt;a href="http://launchpad.net/ubuntu/+source/apt-listchanges/2.72ubuntu6.1"&gt;2.72ubuntu6.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apt-listchanges &lt;a href="http://launchpad.net/ubuntu/+source/apt-listchanges/2.74ubuntu3.1"&gt;2.74ubuntu3.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Felipe Sateler discovered that apt-listchanges did not use safe paths when
importing additional Python libraries.  A local attacker could exploit
this and execute arbitrary commands as the user running apt-listchanges.
&lt;/p&gt;

      </description>
      <pubDate>Fri, 18 Jan 2008 23:07:41 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-571-2] X.org regression</title>
      <guid>http://www.ubuntu.com/usn/usn-571-2</guid>
      <link>http://www.ubuntu.com/usn/usn-571-2</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-571-2           January 19, 2008
xorg-server regression
&lt;a href="https://launchpad.net/bugs/183969"&gt;Bug 183969&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/1:1.0.2-0ubuntu10.10"&gt;1:1.0.2-0ubuntu10.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/1:1.1.1-0ubuntu12.5"&gt;1:1.1.1-0ubuntu12.5&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/2:1.2.0-3ubuntu8.3"&gt;2:1.2.0-3ubuntu8.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;xserver-xorg-core &lt;a href="http://launchpad.net/ubuntu/+source/xserver-xorg-core/2:1.3.0.0.dfsg-12ubuntu8.3"&gt;2:1.3.0.0.dfsg-12ubuntu8.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart your session to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
USN-571-1 fixed vulnerabilities in X.org.  The upstream fixes were
incomplete, and under certain situations, applications using the MIT-SHM
extension (e.g. Java, wxWidgets) would crash with BadAlloc X errors.
This update fixes the problem.&lt;/p&gt;&lt;p&gt;We apologize for the inconvenience.&lt;/p&gt;&lt;p&gt;Original advisory details:&lt;/p&gt;&lt;p&gt; Multiple overflows were discovered in the XFree86-Misc, XInput-Misc,
 TOG-CUP, EVI, and MIT-SHM extensions which did not correctly validate
 function arguments.  An authenticated attacker could send specially
 crafted requests and gain root privileges. (CVE-2007-5760, CVE-2007-6427,
 CVE-2007-6428, CVE-2007-6429)
 
 It was discovered that the X.org server did not use user privileges when
 attempting to open security policy files.  Local attackers could exploit
 this to probe for files in directories they would not normally be able
 to access.  (CVE-2007-5958)
 
 It was discovered that the PCF font handling code did not correctly
 validate the size of fonts.  An authenticated attacker could load a
 specially crafted font and gain additional privileges.  (CVE-2008-0006)
&lt;/p&gt;

      </description>
      <pubDate>Sat, 19 Jan 2008 07:33:40 +0000</pubDate>
      <dc:creator>Kees Cook &lt;kees@ubuntu.com&gt;</dc:creator>
      <author>Kees Cook &lt;kees@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-573-1] PulseAudio vulnerability</title>
      <guid>http://www.ubuntu.com/usn/usn-573-1</guid>
      <link>http://www.ubuntu.com/usn/usn-573-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-573-1           January 31, 2008
pulseaudio vulnerability
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0008"&gt;CVE-2008-0008&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;pulseaudio &lt;a href="http://launchpad.net/ubuntu/+source/pulseaudio/0.9.5-5ubuntu4.2"&gt;0.9.5-5ubuntu4.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;pulseaudio &lt;a href="http://launchpad.net/ubuntu/+source/pulseaudio/0.9.6-1ubuntu2.1"&gt;0.9.6-1ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that PulseAudio did not properly drop privileges
when running as a daemon. Local users may be able to exploit this
and gain privileges. The default Ubuntu configuration is not
affected.
&lt;/p&gt;

      </description>
      <pubDate>Thu, 31 Jan 2008 22:24:46 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-574-1] Linux kernel vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-574-1</guid>
      <link>http://www.ubuntu.com/usn/usn-574-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-574-1          February 04, 2008
linux-source-2.6.17/20/22 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-6058"&gt;CVE-2006-6058&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3107"&gt;CVE-2007-3107&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4567"&gt;CVE-2007-4567&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4849"&gt;CVE-2007-4849&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4997"&gt;CVE-2007-4997&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5093"&gt;CVE-2007-5093&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5500"&gt;CVE-2007-5500&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5501"&gt;CVE-2007-5501&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5966"&gt;CVE-2007-5966&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6063"&gt;CVE-2007-6063&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6151"&gt;CVE-2007-6151&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6206"&gt;CVE-2007-6206&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6417"&gt;CVE-2007-6417&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0001"&gt;CVE-2008-0001&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.17-12-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-386/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-generic/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-hppa32/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-hppa64/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-itanium/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-mckinley/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc-smp/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-powerpc64-smp/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-server/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-server-bigiron &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-server-bigiron/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-sparc64/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.17-12-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.17-12-sparc64-smp/2.6.17.1-12.43"&gt;2.6.17.1-12.43&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.20-16-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-386/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-generic/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-hppa32/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-hppa64/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-itanium/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-lowlatency &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-lowlatency/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-mckinley/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc-smp/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-powerpc64-smp/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-server/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-server-bigiron &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-server-bigiron/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-sparc64/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.20-16-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.20-16-sparc64-smp/2.6.20-16.34"&gt;2.6.20-16.34&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;linux-image-2.6.22-14-386 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-386/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-cell &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-cell/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-generic &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-generic/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-hppa32 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-hppa32/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-hppa64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-hppa64/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-itanium &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-itanium/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-lpia &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-lpia/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-lpiacompat &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-lpiacompat/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-mckinley &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-mckinley/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc-smp/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-powerpc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-powerpc64-smp/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-rt &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-rt/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-server &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-server/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-sparc64 &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-sparc64/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-sparc64-smp &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-sparc64-smp/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-ume &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-ume/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-virtual &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-virtual/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;li&gt;linux-image-2.6.22-14-xen &lt;a href="http://launchpad.net/ubuntu/+source/linux-image-2.6.22-14-xen/2.6.22-14.51"&gt;2.6.22-14.51&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
The minix filesystem did not properly validate certain filesystem
values. If a local attacker could trick the system into attempting
to mount a corrupted minix filesystem, the kernel could be made to
hang for long periods of time, resulting in a denial of service.
This was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2006-6058)&lt;/p&gt;&lt;p&gt;The signal handling on PowerPC systems using HTX allowed local users
to cause a denial of service via floating point corruption. This was
only vulnerable in Ubuntu 6.10 and 7.04. (CVE-2007-3107)&lt;/p&gt;&lt;p&gt;The Linux kernel did not properly validate the hop-by-hop IPv6
extended header. Remote attackers could send a crafted IPv6 packet
and cause a denial of service via kernel panic. This was only
vulnerable in Ubuntu 7.04. (CVE-2007-4567)&lt;/p&gt;&lt;p&gt;The JFFS2 filesystem with ACL support enabled did not properly store
permissions during inode creation and ACL setting. Local users could
possibly access restricted files after a remount.  This was only
vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4849)&lt;/p&gt;&lt;p&gt;Chris Evans discovered an issue with certain drivers that use the
ieee80211_rx function. Remote attackers could send a crafted 802.11
frame and cause a denial of service via crash. This was only
vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-4997)&lt;/p&gt;&lt;p&gt;Alex Smith discovered an issue with the pwc driver for certain webcam
devices. A local user with physical access to the system could remove
the device while a userspace application had it open and cause the USB
subsystem to block. This was only vulnerable in Ubuntu 7.04.
(CVE-2007-5093)&lt;/p&gt;&lt;p&gt;Scott James Remnant discovered a coding error in ptrace. Local users
could exploit this and cause the kernel to enter an infinite loop.
This was only vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-5500)&lt;/p&gt;&lt;p&gt;It was discovered that the Linux kernel could dereference a NULL
pointer when processing certain IPv4 TCP packets. A remote attacker
could send a crafted TCP ACK response and cause a denial of service
via crash. This was only vulnerable in Ubuntu 7.10. (CVE-2007-5501)&lt;/p&gt;&lt;p&gt;Warren Togami discovered that the hrtimer subsystem did not properly
check for large relative timeouts. A local user could exploit this and
cause a denial of service via soft lockup. (CVE-2007-5966)&lt;/p&gt;&lt;p&gt;Venustech AD-LAB discovered a buffer overflow in the isdn net
subsystem. This issue is exploitable by local users via crafted input
to the isdn_ioctl function. (CVE-2007-6063)&lt;/p&gt;&lt;p&gt;It was discovered that the isdn subsystem did not properly check for
NULL termination when performing ioctl handling. A local user could
exploit this to cause a denial of service. (CVE-2007-6151)&lt;/p&gt;&lt;p&gt;Blake Frantz discovered that when a root process overwrote an existing
core file, the resulting core file retained the previous core file's
ownership. Local users could exploit this to gain access to sensitive
information. (CVE-2007-6206)&lt;/p&gt;&lt;p&gt;Hugh Dickins discovered the when using the tmpfs filesystem, under
rare circumstances, a kernel page may be improperly cleared. A local
user may be able to exploit this and read sensitive kernel data or
cause a denial of service via crash. (CVE-2007-6417)&lt;/p&gt;&lt;p&gt;Bill Roman discovered that the VFS subsystem did not properly check
access modes. A local user may be able to gain removal privileges on
directories. (CVE-2008-0001)
&lt;/p&gt;

      </description>
      <pubDate>Mon, 04 Feb 2008 18:17:28 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-575-1] Apache vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-575-1</guid>
      <link>http://www.ubuntu.com/usn/usn-575-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-575-1          February 04, 2008
apache2 vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-3918"&gt;CVE-2006-3918&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3847"&gt;CVE-2007-3847&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-4465"&gt;CVE-2007-4465&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-5000"&gt;CVE-2007-5000&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6388"&gt;CVE-2007-6388&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6421"&gt;CVE-2007-6421&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-6422"&gt;CVE-2007-6422&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0005"&gt;CVE-2008-0005&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apache2-mpm-perchild &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-perchild/2.0.55-4ubuntu2.3"&gt;2.0.55-4ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-prefork &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-prefork/2.0.55-4ubuntu2.3"&gt;2.0.55-4ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-worker &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-worker/2.0.55-4ubuntu2.3"&gt;2.0.55-4ubuntu2.3&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apache2-mpm-perchild &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-perchild/2.0.55-4ubuntu4.2"&gt;2.0.55-4ubuntu4.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-prefork &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-prefork/2.0.55-4ubuntu4.2"&gt;2.0.55-4ubuntu4.2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-worker &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-worker/2.0.55-4ubuntu4.2"&gt;2.0.55-4ubuntu4.2&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apache2-mpm-event &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-event/2.2.3-3.2ubuntu2.1"&gt;2.2.3-3.2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-perchild &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-perchild/2.2.3-3.2ubuntu2.1"&gt;2.2.3-3.2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-prefork &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-prefork/2.2.3-3.2ubuntu2.1"&gt;2.2.3-3.2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-worker &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-worker/2.2.3-3.2ubuntu2.1"&gt;2.2.3-3.2ubuntu2.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;apache2-mpm-event &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-event/2.2.4-3ubuntu0.1"&gt;2.2.4-3ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-perchild &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-perchild/2.2.4-3ubuntu0.1"&gt;2.2.4-3ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-prefork &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-prefork/2.2.4-3ubuntu0.1"&gt;2.2.4-3ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;li&gt;apache2-mpm-worker &lt;a href="http://launchpad.net/ubuntu/+source/apache2-mpm-worker/2.2.4-3ubuntu0.1"&gt;2.2.4-3ubuntu0.1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
In general, a standard system upgrade is sufficient to effect the
necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)&lt;/p&gt;&lt;p&gt;It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date headers and cause a denial of
service via application crash. By default, mod_proxy is disabled in
Ubuntu. (CVE-2007-3847)&lt;/p&gt;&lt;p&gt;It was discovered that mod_autoindex did not force a character set,
which could result in browsers becoming vulnerable to cross-site
scripting attacks when processing the output. (CVE-2007-4465)&lt;/p&gt;&lt;p&gt;It was discovered that mod_imap/mod_imagemap did not force a
character set, which could result in browsers becoming vulnerable
to cross-site scripting attacks when processing the output. By
default, mod_imap/mod_imagemap is disabled in Ubuntu. (CVE-2007-5000)&lt;/p&gt;&lt;p&gt;It was discovered that mod_status when status pages were available,
allowed for cross-site scripting attacks. By default, mod_status is
disabled in Ubuntu. (CVE-2007-6388)&lt;/p&gt;&lt;p&gt;It was discovered that mod_proxy_balancer did not sanitize its input,
which could result in browsers becoming vulnerable to cross-site
scripting attacks when processing the output. By default,
mod_proxy_balancer is disabled in Ubuntu. This was only vulnerable
in Ubuntu 7.04 and 7.10. (CVE-2007-6421)&lt;/p&gt;&lt;p&gt;It was discovered that mod_proxy_balancer could be made to
dereference a NULL pointer. A remote attacker could send a crafted
request and cause a denial of service via application crash. By
default, mod_proxy_balancer is disabled in Ubuntu. This was only
vulnerable in Ubuntu 7.04 and 7.10. (CVE-2007-6422)&lt;/p&gt;&lt;p&gt;It was discovered that mod_proxy_ftp did not force a character set,
which could result in browsers becoming vulnerable to cross-site
scripting attacks when processing the output. By default,
mod_proxy_ftp is disabled in Ubuntu. (CVE-2008-0005)
&lt;/p&gt;

      </description>
      <pubDate>Tue, 05 Feb 2008 00:14:49 +0000</pubDate>
      <dc:creator>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</dc:creator>
      <author>Jamie Strandboge &lt;jamie@ubuntu.com&gt;</author>
    </item>
    <item>
      <title>[USN-576-1] Firefox vulnerabilities</title>
      <guid>http://www.ubuntu.com/usn/usn-576-1</guid>
      <link>http://www.ubuntu.com/usn/usn-576-1</link>
      <description>
&lt;hr /&gt;
&lt;pre&gt;Ubuntu Security Notice USN-576-1          February 08, 2008
firefox vulnerabilities
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0412"&gt;CVE-2008-0412&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0413"&gt;CVE-2008-0413&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0414"&gt;CVE-2008-0414&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0415"&gt;CVE-2008-0415&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0416"&gt;CVE-2008-0416&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0417"&gt;CVE-2008-0417&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0418"&gt;CVE-2008-0418&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0419"&gt;CVE-2008-0419&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0420"&gt;CVE-2008-0420&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0591"&gt;CVE-2008-0591&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0592"&gt;CVE-2008-0592&lt;/a&gt;, &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0593"&gt;CVE-2008-0593&lt;/a&gt;,
&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0594"&gt;CVE-2008-0594&lt;/a&gt;
&lt;/pre&gt;
&lt;hr /&gt;
A security issue affects the following Ubuntu releases:
&lt;ul&gt;
  &lt;li&gt;
  Ubuntu 6.06 LTS&lt;/li&gt;&lt;li&gt;Ubuntu 6.10&lt;/li&gt;&lt;li&gt;Ubuntu 7.04&lt;/li&gt;&lt;li&gt;Ubuntu 7.10
  &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
&lt;/p&gt;
&lt;p&gt;
The problem can be corrected by upgrading your system to the
following package versions:
&lt;/p&gt;
&lt;dl&gt;
  &lt;dt&gt;Ubuntu 6.06 LTS&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/1.5.dfsg+1.5.0.15~prepatch080202a-0ubuntu1"&gt;1.5.dfsg+1.5.0.15~prepatch080202a-0ubuntu1&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 6.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.12+0nobinonly+2-0ubuntu0.6.10"&gt;2.0.0.12+0nobinonly+2-0ubuntu0.6.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.04&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.12+1nobinonly+2-0ubuntu0.7.4"&gt;2.0.0.12+1nobinonly+2-0ubuntu0.7.4&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;&lt;dt&gt;Ubuntu 7.10&lt;/dt&gt;&lt;dd&gt;&lt;ul&gt;&lt;li&gt;firefox &lt;a href="http://launchpad.net/ubuntu/+source/firefox/2.0.0.12+2nobinonly+2-0ubuntu0.7.10"&gt;2.0.0.12+2nobinonly+2-0ubuntu0.7.10&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/dd&gt;
&lt;/dl&gt;
&lt;p&gt;
After a standard system upgrade you need to restart firefox to effect
the necessary changes.
&lt;/p&gt;
Details follow:
&lt;p&gt;
Various flaws were discovered in the browser and JavaScript engine.
By tricking a user into opening a malicious web page, an attacker
could execute arbitrary code with the user's privileges.
(CVE-2008-0412, CVE-2008-0413)&lt;/p&gt;&lt;p&gt;Flaws were discovered in the file upload form control. A malicious
website could force arbitrary files from the user's computer to be
uploaded without consent. (CVE-2008-0414)&lt;/p&gt;&lt;p&gt;Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges. (CVE-2008-0415)&lt;/p&gt;&lt;p&gt;Various flaws were discovered in character encoding handling. If a
user were ticked into opening a malicious web page, an attacker
could perform cross-site scripting attacks. (CVE-2008-0416)&lt;/p&gt;&lt;p&gt;Justin Dolske discovered a flaw in the password saving mechanism. By
tricking a user into opening a malicious web page, an attacker could
corrupt the user's stored passwords. (CVE-2008-0417)&lt;/p&gt;&lt;p&gt;Gerry Eisenhaur discovered that the chrome URI scheme did not properly
guard against directory traversal. Under certain circumstances, an
attacker may be able to load files or steal session data. Ubuntu is
not vulnerable in the default installation. (CVE-2008-0418)&lt;/p&gt;&lt;p&gt;David Bloom discovered flaws in the way images are treated by the
browser. A malicious website could exploit this to steal the user's
history information, crash the browser and/or possibly execute
arbitrary code with the user's privileges. (CVE-2008-0419)&lt;/p&gt;&lt;p&gt;Flaws were discovered in the BMP decoder. By tricking a user into
opening a specially crafted BMP file, an attacker could obtain
sensitive information. (CVE-2008-0420)&lt;/p&gt;&lt;p&gt;Michal Zalewski discovered flaws with timer-enabled security dialogs.
A malicious website could force the user to confirm a security dialog
without explicit consent. (CVE-2008-0591)&lt;/p&gt;&lt;p&gt;It was discovered that Firefox mis